Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› What is the difference between low and medium…
Authentication, Authorisation & Trust

What is the difference between low and medium identity confidence under GPG 45?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Authentication, Authorisation & Trust

Low confidence reduces risk by confirming that each piece of evidence appears genuine, the claimed identity exists, and the person matches the photo or biometric data on the evidence. Medium confidence goes further by requiring very strong evidence and stronger assurance that the identity is real, valid, and not being misused by an impostor. The difference is the depth of assurance.

What low confidence is trying to establish

Low identity confidence is about establishing a workable baseline that the identity evidence is genuine enough to trust for a lower assurance decision. In practice, that means the checker is trying to confirm document authenticity, that the claimed identity exists, and that the person presenting the evidence matches the photo or biometric data on it.

The important point is that low confidence is still evidence-based. It is not a casual acceptance of a claim, but it tolerates less stringent proof than higher levels. That makes it suitable where the consequence of error is limited or where the process will be followed by additional controls later.

For organisations dealing with identity proofing at scale, the operational question is often whether the evidence chain is strong enough to resist obvious forgery and mismatched presentation, not whether it is strong enough to support the highest assurance outcome. That distinction matters because low confidence is designed for the first layer of trust, not the final one.

How medium confidence raises the assurance bar

Medium identity confidence requires a stronger evidential foundation and more assurance that the identity is real, valid, and not being used by an impostor. It goes beyond confirming that the documents look genuine and the face matches, and instead expects a more robust check that the identity claim can survive closer scrutiny.

That usually means the process is less forgiving of weak evidence, inconsistencies, or anything that suggests impersonation. The practical effect is a lower false-acceptance tolerance, because the decision is meant to support more consequential identity use cases than a low-confidence result would.

Seen another way, medium confidence does not change the type of question being asked, it changes how hard the verifier has to work before saying yes. The identity is still being established, but with stronger confidence that the person is truly entitled to the identity being presented.

What the difference means in practice

The difference between low and medium confidence is the depth of assurance, not a completely different identity process. Low confidence asks whether the evidence appears genuine and internally consistent enough to trust at a basic level, while medium confidence asks whether the identity can be trusted with materially stronger resistance to fraud, impersonation, and misuse.

That difference affects downstream decisions. A medium-confidence result is more defensible when the identity will be used for higher-value access, stronger regulatory expectations, or a process where identity failure would have a larger operational or security consequence. Low confidence may be adequate for lower-risk enrolment or a step that will be supplemented later, but it is a weaker basis for relying on the identity alone.

Practitioners should treat the two levels as assurance tiers, not as labels. The right question is not which one sounds more secure, but whether the identity proofing outcome is proportionate to the decision that will depend on it.

Risk and Threat Considerations

The main risk is over-trusting a result that was only intended to provide limited assurance. If a low-confidence identity is used where medium confidence is actually needed, an impostor, forged evidence, or a weak presentation check can become the point of failure.

Failure mechanism: The verifier accepts evidence that is authentic-looking but not strong enough to exclude identity fraud, document tampering, or a mismatch between the presented person and the claimed identity.

Impact: The organisation may grant access, onboarding, or other trust decisions to the wrong person, increasing fraud exposure and weakening the security of downstream processes that assume the identity is dependable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesGPG 45 confidence levels are identity proofing concepts aligned to assurance-based identity guidance.
Recommendation — Map the required proofing confidence to the transaction risk and verify evidence strength accordingly.
ISO/IEC 27001:2022A.5.16 — Identity managementIdentity confidence levels influence how identities are established and governed before access is granted.
Recommendation — Define proofing thresholds and approval criteria for each identity assurance tier.
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)The question concerns proving external identities before they are trusted.
IA-12 — Identity ProofingGPG 45 confidence is fundamentally about the strength of identity proofing.
Recommendation — Use stronger identity proofing for non-organizational users when downstream risk is higher. Set proofing evidence requirements that match the assurance level needed.

Practitioner Guidance

What to verify: Align the confidence level to the decision that will consume it. If the identity will be used for meaningful access, customer actions, or regulated processing, make sure the evidence threshold and match strength are sufficient for that use case, not just for initial enrolment.

Decision rule: Treat low confidence as a limited-assurance outcome that usually needs compensating controls or later uplift, while medium confidence should be reserved for cases where stronger resistance to impersonation is genuinely required.

Practitioner takeaway: The practical control is proportionality, use the lowest confidence level that still safely supports the downstream decision, and do not let a weaker proofing result carry a stronger trust obligation than it can justify.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org